Description
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ROLLUPPLUGINDEVSERVER-590124
Related Vulnerabilities
CVE-2021-43787 Vulnerability in npm package nodebb
CVE-2021-3918 Vulnerability in npm package json-schema
CVE-2023-49376 Vulnerability in maven package com.jfinal:jfinal
CVE-2021-23348 Vulnerability in npm package portprocesses
CVE-2021-23337 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash